FedRAMP Marketplace Listing vs. Agency Authority to Operate (ATO)

Having a FedRAMP Marketplace listing versus having an agency ATO are related, but not the same thing. A Marketplace listing means FedRAMP is tracking a product — at any status, from just starting out to fully authorized. An agency ATO means a specific federal agency actually assessed the system and accepted the risk of using it.

A platform vendor can hold a complete agency ATO without ever appearing on the Marketplace. So if you search for a vendor and come up empty, that alone doesn’t rule them out — it just means you have to verify a different way.

What the FedRAMP Marketplace is (and isn’t)

The Marketplace is a catalog of cloud products FedRAMP is tracking, along with their status (Ready, In Process, Authorized) and impact level (Moderate or High or A through D). It’s a genuinely useful discovery and verification tool. But a listing by itself doesn’t mean a platform is FedRAMP-certified (or “FedRAMP-authorized”) You have to actually read the status field.

A product can be listed as “In Process” without being authorized for anything — meaning it isn’t yet cleared to handle federal data. The listing is simply tracking progress; it isn’t a stamp of approval on its own.

PMO-published listing vs. Agency ATO 

A PMO-published listing is the same thing as being listed “Certified” (the designation that replaced “Authorized” as of June 2026) on the FedRAMP Marketplace — the FedRAMP Program Management Office (PMO) reviews the package itself and approves it for reuse across every agency, not just one.

An agency ATO is issued when one federal agency assesses a system against the FedRAMP baseline and accepts the risk of using it in its own environment. 

Both routes can be assessed against the exact same High (soon to be Class D) baseline. The difference is scope — one agency vs. government-wide — and where the authorization is recorded, not whether either one is “real.”

How a product gets listed

Listing generally happens once a product engages the FedRAMP process with an agency sponsor and pursues a PMO-tracked authorization path. From there, the Marketplace entry updates to reflect its progress — Ready, then In Process, then Authorized, if it gets that far. This route is built around government-wide reuse: once listed as Authorized, other agencies can lean on that same package instead of starting from scratch.

Why a vendor may hold an ATO but not be listed on FedRAMP Marketplace

If a platform earned its authorization through a direct agency ATO rather than the PMO-tracked path, it may never show up in the Marketplace directory at all. That’s a recording distinction, not a security gap. The underlying assessment work is the same either way.

Ruling a vendor out purely because you can’t find them on the Marketplace would be a mistake. The right move is to ask directly for the ATO details and verify from there.

The 5-point verification checklist

Whether or not a vendor shows up on the Marketplace, these five checks tell you what you actually need to know:

  •     Ask for the ATO attestation letter — who issued it, and when.
  •     Confirm the impact level — Moderate or High (High corresponds to the newer Class D designation).
  •     Identify the authorizing agency — and consider whether that agency’s risk profile is credible for your own use case.
  •     Request the System Security Plan and 3PAO assessment — the actual evidence behind the authorization, not just the headline claim.
  •     Confirm it’s the platform’s own ATO — not just the FedRAMP-authorized (or FedRAMP-certified) cloud infrastructure it happens to be hosted on.

Common mistakes when checking a vendor’s status

  •     Treating “not on the Marketplace” as disqualifying. A direct agency ATO is a legitimate route that may never appear in the directory.
  •     Stopping at the listing itself. Ready and In Process both show up in the Marketplace — neither one clears a platform for federal data.
  •     Assuming a listing means the whole product is covered. Always check that the listing matches the specific product and edition you’re buying, not just the vendor’s name.

FAQs

Does a Marketplace listing mean a vendor is authorized?

Not by itself. A listing shows FedRAMP is tracking a product at some status — Ready, In Process, or Authorized. Only the “Authorized” status means it’s cleared to handle federal data.

What is a PMO-published authorization?

A PMO-published authorization is one reviewed and formally listed by the FedRAMP Program Management Office (PMO) — the team within the General Services Administration (GSA) that runs FedRAMP day to day. Once the PMO publishes it, the authorization appears as “Authorized” on the FedRAMP Marketplace, and any federal agency can reuse that same package under OMB’s presumption of adequacy instead of reassessing it themselves. It’s the government-wide route, as opposed to an agency ATO, which one agency assesses and issues on its own.

What is an Authority to Operate (ATO)?

An ATO is the formal approval a federal agency issues before a system goes live, certifying its security risk has been assessed and accepted. A FedRAMP High ATO means it was assessed against the FedRAMP High baseline.

Why would a vendor choose an agency ATO over a Marketplace-listed authorization?

An agency ATO can be faster to obtain when a vendor already has a strong relationship with one sponsoring agency, since it doesn’t require pursuing the government-wide PMO-published process. 

Is a Marketplace-listed authorization stronger than an agency ATO?

Not inherently. Both can be assessed against the identical FedRAMP baseline, including independent 3PAO assessment and continuous monitoring. The Marketplace-listed route is built for easier government-wide reuse; an agency ATO is scoped to the authorizing agency, but the underlying security work can be just as rigorous.

Can a vendor have an ATO but not be on the Marketplace?

Yes. A platform that earned a direct agency ATO, rather than going through the PMO-tracked path, may never appear in the Marketplace directory. That’s a recording distinction, not a security gap — the agency still assessed the system against the same baseline.

What does “FedRAMP status” mean?

It’s shorthand for two things at once: how far along a platform is in the approval process (Ready, In Process, Authorized), and what level of data it’s cleared to handle (Moderate or High).

Can I use a platform that’s “In Process”?

No. Only a completed authorization — at the impact level your data needs — clears a platform for federal use.

What does “FedRAMP Certified” mean?

It’s FedRAMP’s newer name for what used to be called “Authorized.” Same requirement, new label. High-level (“Class D”) certification still means the toughest standard on the books.

What does “FedRAMP compliance” actually mean?

FedRAMP itself doesn’t use “compliant” as an official designation — a system is Ready, In Process, or Authorized (increasingly called “Certified”). Vendors often use “FedRAMP compliant” to mean their infrastructure meets FedRAMP standards, without necessarily having the application itself independently assessed and authorized. Treat “compliant” as a marketing term to ask follow-up questions about, not a credential on its own.

How long does it take to go from In Process to Authorized?

It varies a lot by agency and platform complexity — anywhere from several months to a couple of years. There’s no fixed timeline, which is exactly why “In Process” alone doesn’t tell you much.

Does an Authorized status ever expire?

Authorized platforms have to go through continuous monitoring to keep their status current. It isn’t a one-time stamp — agencies expect ongoing proof the security posture holds up.

What’s the difference between FedRAMP Moderate and High?

It comes down to data sensitivity. Moderate covers serious-impact data (~325 controls). High covers the most sensitive data (400+ controls) — including a lot of federal health information. A Moderate platform can’t take on High-level work.

Which EHRs have a FedRAMP High ATO?

Very few. VSee holds a FedRAMP High ATO issued by HHS ASPR; most others are Moderate, In Process, single-agency, or not FedRAMP. See the comparison →

How do I verify a vendor’s FedRAMP status?

Check the FedRAMP Marketplace; if a vendor isn’t listed, request its ATO letter, impact level, authorizing agency, and System Security Plan — and confirm it’s the platform’s own ATO, not just its hosting.

How long and how expensive is a FedRAMP authorization?

Typically 12–18 months plus significant cost and staffing (several hundred thousand to a few million) — which is why deploying a platform that already holds a FedRAMP authorization removes the biggest time and risk from an agency’s project.

What is the FedRAMP authorization process? 

A platform is assessed against the FedRAMP control baseline by an accredited third-party assessor, and a federal agency reviews the results and issues an ATO. The full path follows the NIST Risk Management Framework:

  1. Categorize the data’s impact level (Low / Moderate / High)
  2. Secure a federal agency sponsor
  3. Implement controls (typically on a FedRAMP-authorized cloud)
  4. Document them in a System Security Plan (SSP)
  5. Independent 3PAO (third-party assessment organization) assessment
  6. Remediate findings (tracked in a POA&M or Plan of Action & Milestones)
  7. Agency issues the ATO
  8. Maintain it through continuous monitoring

Because this is long and demanding, deploying a platform that has already completed it removes most of that burden from your agency.

Where VSee stands

VSee holds an agency-specific FedRAMP High ATO issued by HHS ASPR, rather than a government-wide, Marketplace-listed authorization. The two are different routes to the same High baseline. VSee’s security package is available to agencies that want to verify the authorization directly. See VSee’s FedRAMP High ATO details →

Sources